Back to skill
Skillv1.0.0
ClawScan security
thesis-results-writer · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 29, 2026, 5:55 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only skill whose requested inputs, behavior, and local reference materials are consistent with its stated purpose of drafting Chinese results chapters; it asks for no credentials or installs and contains no hidden endpoints.
- Guidance
- This skill appears coherent and low-risk, but consider the following before enabling it: 1) Provide only de-identified participant data and avoid sharing personally identifiable or sensitive information in inputs. 2) The skill will not invent numbers—if you want a full draft you must supply actual results; otherwise you'll get a skeleton with placeholders. 3) Check your institution's policies on AI-assisted writing and plagiarism; use the generated text as a draft and verify formatting, statistics, and interpretation before submission. 4) Because the skill can be invoked by the agent (normal default), review any agent autonomy settings you use if you want to restrict automatic use. If you want further assurance, you can request the author/source of the skill or a checksum/commit history; absence of a homepage or author contact means provenance is limited.
Review Dimensions
- Purpose & Capability
- okThe skill's name and description (writing Chinese results chapters) match the SKILL.md and the included reference guide. It requires no binaries, credentials, or config paths that would be unrelated to writing results text.
- Instruction Scope
- okRuntime instructions are limited to reading the supplied local reference (references/results-writing-guide.md) and the user's provided research data or descriptions. The guide explicitly forbids fabricating data and does not instruct reading system files, accessing external endpoints, or collecting unrelated information.
- Install Mechanism
- okThere is no install specification and no code files that would be written to disk or executed. Being instruction-only minimizes installation risk.
- Credentials
- okThe skill declares no required environment variables, no primary credential, and no config paths. The information it asks the user to provide (data, tables, themes, quotes) is appropriate and proportional to its stated function.
- Persistence & Privilege
- okalways is false and the skill does not request permanent/system-level presence or modify other skills. disable-model-invocation is false (normal default) allowing autonomous invocation, which by itself is expected for skills and is not combined here with other red flags.
